securityonline.info 18 Sept 2026, 09:41 UTC

Synology Patches Critical NAS Flaws Allowing Unauthenticated File Access

Synology Patches Critical NAS Flaws Allowing Unauthenticated File Access
CyberSIXT Evidence Panel

SYNOLOGY has patched eight vulnerabilities in DiskStation Manager (DSM), including two critical, unauthenticated flaws affecting its network-attached storage devices. Advisory SA_26_13 rates CVE-2026-13684 and CVE-2026-13639 at CVSS 9.8; both can allow a remote attacker to read or write arbitrary files and cause denial of service without logging in or requiring user interaction. CVE-2026-13684 is an output-encoding issue in the SCGI component, while CVE-2026-13639 involves insufficient entropy in login logic.

The remaining six vulnerabilities range from high to low severity. CVE-2026-13673 and CVE-2026-6205 allow authenticated users to write files through the LDAP and Upload APIs. Other issues include CRLF injection, cross-site scripting and SQL injection, with the latter two requiring administrator privileges. The affected DSM branches are 7.2.1, 7.2.2, 7.3 and 7.4. Synology reports that none of the eight flaws is being actively exploited, and the article notes no public proof of concept.

Synology lists no workaround and advises users to install the appropriate update for their branch: 7.4-90075, 7.3.2-86009-4, 7.2.2-72806-9 or 7.2.1-69057-12 and later. The advisory also recommends limiting internet exposure of NAS devices and restricting administrator access.

View full article

Article by CyberSIXT